Articles by Paul Bryant

Paul is a CISSP-certified technology leader with over 30 years of experience in technology management and software development. He brings a rare combination of deep technical knowledge and commercial acumen, with a strong background in business and process design.

As Strategic Director at phew, he focuses on cybersecurity strategy, ensuring services stay ahead of emerging threats and meet rigorous client standards.

OWASP AISVS: The AI Security Standard the Industry Has Been Missing

On 24 June 2026, OWASP released version 1.0 of the Artificial Intelligence Security Verification Standard, AISVS for short, and for those of us who test web applications (and increasingly the AI features bolted onto them) this is the standard we have been waiting for. Until recently, testing an AI-enabled feature meant improvising. Testers could borrow adjacent controls from the OWASP Application Security Verification Standard (ASVS), lean on the OWASP Top 10 for LLM Applications for a sense of the risk landscape, and draw techniques and methodology from the AI Testing Guide that OWASP published in late 2025. But the rest

Read more

AI-Assisted Security Testing: What’s Real, What’s Hype, and What It Means for Your SaaS

One question is starting to come up more frequently in conversations about penetration testing, and it is an entirely reasonable one. People are querying why, if Claude, Codex Security, or any number of other AI tools can autonomously scan a codebase, identify vulnerabilities, and generate reports, do you still need to engage a pen tester? It is a fair question, but the answer is nuanced and deserves a depth of discussion (and is certainly more nuanced than the vendors selling AI security tooling or the sceptics dismissing it would have you believe). There is no denying that AI security tools

Read more

The AI Vulnerability Storm Is Coming. Here’s What SaaS Teams Need to Know.

A group of the most credible voices in cybersecurity just published a document that deserves your full attention. The “AI Vulnerability Storm” briefing, authored by contributors including the CISO of Google, the former Director of CISA, the former Cybersecurity Director of the NSA, and the CEO of SANS, is not a vendor whitepaper or a think piece. It’s a coordinated warning from practitioners who collectively have more signal on where this is heading than almost anyone else on the planet. When this group agrees on something, it’s worth treating that consensus seriously. The trigger for the briefing is Anthropic’s Claude

Read more

Security Budgets & Why They Matter

Did you spend 0% of your website’s budget on security? What about your new web application, new API, or even your new e-commerce store? We’re talking about independent security testing, auditing and verification, rather than the things your developers did (or apparently did) in terms of security. Be honest. You wouldn’t be alone. We work with a lot of developers, development shops, and founders, and we understand how things are. The competing pressures that are placed on budget and time, that come from a variety of places. We understand how busy web app developers typically are, and how many ventures

Read more

Where Are Your Hackers Located?

Interestingly it doesn’t really matter. The thing to know is that they’re not located anywhere in particular. Or rather, wherever they are based geographically doesn’t matter, because they can appear to come from anywhere on the internet. And because that’s true for the attackers, it is also true for your pen testers. Although we’re based in New Zealand, more than half of our pen testing is for organisations and targets further afield. In the same way that attackers can target any website, webstore, web portal, web application, API or IP address on the internet, we can pen test any target

Read more

Do You Test Pens?

Do You Test Pens? “Literally, what do you do all day?” That’s a question we get from time to time, perhaps because what we do is not well understood. Well, we do pen testing. “OK, but what is that?  Do you test pens?  That sounds boring.” Yes, that would probably be boring. But no, we don’t test pens. Instead, we test whether your systems can be breached, or “penetrated”. That’s a long word to keep typing, and also has connotations you might find in the Urban Dictionary, so everyone just says “pen testing”. “Got it. So what does that look

Read more

Why caring is important in security

Why caring is important in security When I started phew, I had very clear intentions about building a solid reputation for caring. “Caring” might seem like a strange word to use when you think of tech. But when you pair it with “security”, it suddenly makes a lot of sense, and even more when you think about the integrity of a professional consultancy. I believe very strongly that that’s what sets us apart in the cyber security field. That, and our very specific approach to penetration testing. You could say our pen testing aligns more closely with the methodical strategy

Read more

The phew Top Ten Greatest Hits (…Of Vulnerabilities)

First Up, The OWASP Top 10 Many of you who work or have backgrounds in web application development or cyber security will be familiar with the OWASP Top 10 project. The OWASP Top 10 is a standard awareness document for developers and web application security, which represents a broad consensus about the most critical security risks (vulnerabilities) applicable to web applications. The OWASP Top 10 was refreshed fairly recently to create the OWASP Top 10 for 2021 ( https://owasp.org/Top10/). Background To The phew Top 10 Although at phew we perform a wide variety of penetration testing (from wired and wireless

Read more

CERT NZ Quarterly Update Q1 2022

The Latest from CERT NZ What’s New? CERT NZ is a central organisation that receives cyber incident reports from both individuals and businesses. It tracks attacks and incidents, and provides advice and alerts. The quarterly updates from CERT provide a valuable snapshot of what’s going on with cyber security in NZ, and give us a useful insight into trends and concerns. Their latest update was released last week. It shows a decrease in the number of incidents reported from last quarter, but an increase in the type and complexity of scams. Decrease in Incidents isn’t the Whole Story There was

Read more
Scroll to Top